Impact
An improper privilege management flaw allows a user configured with the all-Java or Flowable workflow adapters, or a BPMN definition that bypasses admin approval, to exploit a REST API call that grants themselves one or more defined Roles. The attacker can obtain the corresponding Entitlements, effectively becoming an administrator and gaining full control over the Syncope deployment. This weakness is classified as CWE‑269 and results in a compromise of confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Apache Software Foundation’s Apache Syncope versions 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.6, and 4.1.0‑M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 or later 4.1.2 or later to resolve the issue.
Risk and Exploitability
The CVSS score is not provided, but the EPSS score is unavailable and the vulnerability is not listed in CISA KEV. The likely attack vector is a remote REST API call that an authenticated user can invoke. Once the endpoint is triggered, the attack is straightforward: the user supplies role identifiers and receives elevated privileges without additional authorization checks. The lack of a hard enforcement of privilege checks makes exploitation low cost and high impact for compromised accounts.
OpenCVE Enrichment